justdan96 tsMuxer
cpe:2.3:a:justdan96:tsmuxer:*:*:*:*:*:*:*
- <= 2.7.0
A denial-of-service vulnerability has been identified in justdan96 tsMuxer versions through 2.7.0. The issue arises in the VvcVpsUnit::setFPS function within the vvc.cpp file. The vulnerability is triggered by manipulating the track_id argument, leading to an assertion failure. This issue must be exploited locally and affects unsupported versions of the software.
Exploitation of this vulnerability causes an assertion failure, leading to a program crash.
The vulnerability can be reproduced by compiling tsMuxer with AddressSanitizer enabled, using Clang as the compiler. After building the application, a proof-of-concept VVC stream that lacks a defined frames-per-second (FPS) value can be processed with tsMuxer. The absence of the FPS value triggers the vulnerability, causing the application to crash with an assertion error.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.